[tor-bugs] #30683 [Applications/Tor Browser]: Properties in dom/locales/$lang/chrome/ allow detecting user locale
Tor Bug Tracker & Wiki
blackhole at torproject.org
Thu Jun 13 07:09:22 UTC 2019
#30683: Properties in dom/locales/$lang/chrome/ allow detecting user locale
---------------------------------------+--------------------------
Reporter: gk | Owner: tbb-team
Type: defect | Status: new
Priority: High | Milestone:
Component: Applications/Tor Browser | Version:
Severity: Normal | Resolution:
Keywords: tbb-fingerprinting-locale | Actual Points:
Parent ID: | Points:
Reviewer: | Sponsor:
---------------------------------------+--------------------------
Comment (by gk):
Replying to [ticket:30683 gk]:
> z3t reported a bunch of issues on HackerOne regarding detection of user
locale with the help of `dom/locales/$lang/chrome/` properties. PoCs done
by z3t:
>
> `dom/dom.properties`:
https://people.torproject.org/~gk/tests/tor_form_locale_leak.html
`<input type="email">` is relevant here as well (thanks to mik317 on
HackerOne for pointing this out).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/30683#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list